Capture-Replay Vulnerability in Medtronic MiniMed Insulin Pumps
CVE-2018-14781

5.3MEDIUM

What is CVE-2018-14781?

The Medtronic MiniMed insulin pumps, when paired with a remote controller and configured with the optional 'easy bolus' and 'remote bolus' features enabled, are subject to a capture-replay attack. This vulnerability enables attackers to intercept and replay wireless communications between the pump and the remote controller, potentially resulting in unauthorized insulin delivery. Users of affected models should be aware of the risks associated with these settings and consider disabling features that could expose them to such threats.

Affected Version(s)

MMT – 511 pump Paradigm All versions

MMT – 512 / MMT – 712 Paradigm x12 All versions

MMT – 515 / MMT – 715 Paradigm x15 All versions

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.